Junglewise Threat Intelligence

CVE-2025-65856: Xiongmai XM530 IP Camera authentication bypass in ONVIF service

CVE-2025-65856 · Severity: critical · CVSS 9.8 · Published 2025-12-22

Executive brief

A critical security flaw has been identified in Xiongmai XM530 IP cameras, which are widely used in residential and commercial surveillance. The vulnerability allows anyone with network access to bypass security controls and view live video feeds, listen to audio, and access sensitive device settings without a password. Because these cameras are often rebranded by hundreds of different manufacturers, many users may be unaware their security systems are exposed to unauthorized remote monitoring.

Technical details

The vulnerability is a missing authentication for critical functions (CWE-306) within the ONVIF web service implementation. The device fails to enforce WS-Security authentication on 31 critical SOAP endpoints, including GetStreamUri, GetSnapshotUri, and GetUsers. An attacker can send unauthenticated SOAP requests to these endpoints to retrieve RTSP stream URIs, enumerate user accounts, and modify device configurations. The flaw is remotely exploitable over common ports (80, 8899) without user interaction. As of the advisory date, no patch is available, and the vendor's security contact infrastructure was reported as non-functional.

Affected products

  • Hangzhou Xiongmai Technology Co., Ltd. XM530V200_X6-WEQ_8M firmware V5.00.R02.000807D8.10010.346624.S.ONVIF 21.06 and likely all V5.00.R02.* versions

Timeline

  • 2025-11: other: Vulnerability discovered during security assessment
  • 2025-12-16: other: CVE-2025-65856 assigned by MITRE
  • 2025-12-17: other: Vendor contact attempted; delivery failed due to misconfigured servers
  • 2025-12-22: advisory: Public disclosure by researcher
  • 2025-12-22: disclosed: NVD publication date

References

Related threats